Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft Threat Intelligence reported that Flax Typhoon, an actor it described as China-based, had targeted dozens of organizations in Taiwan since at least mid-2021. Its August 24, 2023 account described an intrusion approach built around exploiting internet-facing systems, web shells, valid accounts, and Windows tools—alongside malware and other attacker tools. Microsoft said the activity suggested espionage and persistent access, but it had not observed the actor pursue its final objectives in this campaign.

What is Flax Typhoon?

Flax Typhoon is the name Microsoft Threat Intelligence used for a threat actor it attributed to China. Microsoft said the activity overlapped with ETHEREAL PANDA and had been active since mid-2021. Those are Microsoft’s assessments, not an independently verified government finding.

In its report published August 24, 2023, Microsoft said the actor targeted dozens of Taiwanese organizations, particularly in government, education, critical manufacturing, and information technology. It also observed some victims in Southeast Asia, North America, and Africa. Microsoft did not provide an exact victim count.

How did Flax Typhoon hack Taiwanese organizations?

Microsoft described a sequence that began with vulnerable public-facing services and continued through remote access, persistence, credential access, and lateral movement. These are the report’s observations of activity as of 2023, not a guarantee that every intrusion followed the same steps.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

1. Exploiting internet-facing applications

The actor exploited known vulnerabilities in public-facing VPN, web, Java, and SQL applications. Microsoft said it then deployed web shells, including China Chopper, to execute commands remotely.

2. Escalating privileges

When the compromised process lacked local administrator privileges, Microsoft observed the actor using tools that exploited known vulnerabilities to elevate access. Examples named in the report include Juicy Potato and BadPotato.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

3. Establishing Windows persistence

With administrator access, the actor used Windows command-line and management tools to enable remote desktop protocol (RDP) access. Microsoft reported that it disabled RDP network-level authentication and changed the registry path associated with Sticky Keys. That change could make the sign-in-screen shortcut launch Task Manager with system privileges, providing a route back into the system.

4. Setting up command and control

Microsoft said the actor downloaded SoftEther VPN using utilities such as PowerShell Invoke-WebRequest, certutil, or bitsadmin, then configured a Windows service to launch the VPN bridge. The executable was sometimes renamed to resemble a Windows component, and Microsoft observed VPN-over-HTTPS.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Moving across systems and seeking credentials

The report describes lateral movement using Windows Remote Management (WinRM) and Windows Management Instrumentation Command-line (WMIC). For credential access, Microsoft observed attempts targeting LSASS process memory and the Security Account Manager (SAM) registry hive, including the use of Mimikatz.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Why did Flax Typhoon use relatively little malware?

Microsoft described the campaign as relying heavily on living-off-the-land techniques: using built-in operating-system utilities and legitimate software to perform actions that can be harder to distinguish from normal administration. The actor also relied on valid accounts and hands-on-keyboard activity rather than depending on a large, conspicuous malware toolkit. Microsoft warned that this combination can make detection and mitigation challenging.

“Minimal malware” does not mean malware-free. Microsoft reported web shells and named tools including China Chopper, Metasploit, Juicy Potato, BadPotato, Mimikatz, and SoftEther VPN. The characterization is about the campaign’s reliance on built-in or normally benign capabilities, not the absence of malicious code or tools.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did Microsoft observe—and what did it not establish?

Microsoft said the activity appeared unusual because relatively little happened after the actor established persistence. It observed discovery and credential-access activity, but said those actions did not appear to lead to further data collection or exfiltration. Microsoft’s summary stated: “Microsoft has not observed Flax Typhoon using this access to conduct additional actions.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The observed persistence and credential access led Microsoft to assess that the actor sought espionage and long-term footholds. However, Microsoft explicitly said it had not observed Flax Typhoon act on its final objectives in this campaign. The report therefore does not establish confirmed espionage collection, data theft, or a destructive outcome.

How can organizations defend against the techniques Microsoft reported?

Microsoft’s recommendations address the stages of the intrusion: reduce exposure to known vulnerabilities, protect accounts and credentials, harden Windows systems, and investigate suspicious changes. No single control is presented as a guarantee against compromise.

Reduce the chance of initial access

  • Prioritize vulnerability and patch management for internet-facing servers and services, and apply Windows security updates.
  • Give public-facing systems extra protection and monitoring. Microsoft recommends input validation, file-integrity and behavioral monitoring, and web application firewalls.
  • Deactivate unused accounts and use strong multifactor authentication. Microsoft specifically mentions hardware security keys and Microsoft Authenticator, as well as passwordless options such as Windows Hello and FIDO2 security keys.

Limit privilege and credential exposure

  • Use unique local administrator passwords managed with Windows LAPS rather than shared local credentials.
  • Apply attack-surface reduction rules and harden LSASS; Microsoft also recommends Credential Guard and memory integrity.
  • Use Defender cloud-delivered protection and endpoint detection and response (EDR) in block mode as part of a broader security program.

Monitor persistence and remote access

  • Monitor registry changes, particularly changes that could affect sign-in behavior or persistence.
  • Review RDP use and network traffic for unexpected remote-access services, VPN bridges, or connections.
  • Use endpoint alerts, behavioral monitoring, and network monitoring to identify activity that may blend in with routine administration.

Respond to suspected compromise

  • Change credentials that may have been compromised.
  • Isolate affected systems and examine them for web shells, unauthorized services, suspicious registry changes, and signs of lateral movement.
  • Where system changes cannot be trusted, consider restoring the machine to a known-good configuration.

What should defenders do with the report’s indicators?

Microsoft’s report includes historical indicators of compromise, but indicators from an August 2023 report should not be treated as current detections without validating that they remain relevant. Organizations can use the described behaviors—such as unexpected web shells, suspicious RDP configuration changes, unusual VPN services, and credential access—as investigation leads, while checking indicators against current threat intelligence and their own telemetry.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.